Sr. GRC Analyst-Enterprise Cybersecurity

Rivian and Volkswagen Group Technologies

$110K — $130K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5 years of GRC or IT compliance experience
  • Bachelor's degree or equivalent
  • Knowledge of ISO/IEC 27001/27002 and TISAX frameworks
  • Experience in audit support and evidence collection
  • Ability to manage a risk register and drive remediation
  • Strong organizational and project management skills
  • Excellent communication skills with diverse stakeholders
  • Willingness to travel domestically and internationally.

Responsibilities

  • Own and manage TISAX and ISO/IEC 27001 certification cycles
  • Maintain ISO 27001 compliance through internal audits and evidence management
  • Support CSMS and software management compliance for automotive infrastructure
  • Oversee the enterprise cybersecurity risk register and reporting
  • Execute risk management processes with Legal coordination
  • Collaborate with cross-functional teams and manage evidence collection
  • Track external partner deliverables and maintain documentation.

Benefits

  • Participation in an annual performance bonus program
  • Eligibility for equity in the form of Restricted Stock Units (RSUs)
  • Comprehensive health coverage and retirement savings options
  • Time off and family planning programs
  • Diverse benefit offerings that vary by country.
Full Job Description
Role Summary

As GRC Analyst, you will own the operational delivery of our information security certifications and enterprise cybersecurity risk program. This is a hands-on individual-contributor role: you will run certification cycles end to end, keep our ISMS evidence audit-ready year-round, operate the enterprise risk register, and coordinate a large group of internal control owners and external partners. You will not set strategy from a distance - you will do the work that earns and keeps our certifications and keeps risk visible and tracked.

Responsibilities
  • Certifications & Audits
    • Own TISAX follow-on certifications: take over subsequent waves and sites after the initial TISAX AL3 assessments (VDA ISA 6.0.3), and manage evidence maintenance, internal self-assessments, corrective-action tracking, re-assessment readiness, and the ongoing ISMS evidence infrastructure.
    • Own ISO/IEC 27001 certification: drive achievement and ongoing maintenance of certification, coordinate internal audits, maintain the Statement of Applicability and control evidence, and manage annual surveillance and recertification activities.
    • Support ISO 9001 efforts as they relate to infrastructure and IT.
    • Support CSMS compliance under UNECE R155 and software update management under UNECE R156 as they apply to enterprise/IT infrastructure - supporting the cybersecurity management system requirements in an automotive JV/supplier environment.
    • Track and drive corrective and preventive actions (CAPA) to closure across all frameworks, holding owners to due dates.
    Risk Management
    • Operate the enterprise cybersecurity risk register end to end: risk intake, assessment, treatment tracking, and reporting.
    • Execute risk management processes in coordination with Legal and in accordance with documented standard operating procedures, including confidentiality classification steps.
    • Produce clear, prioritized risk reporting for the Sr. Manager, Enterprise Cybersecurity and other stakeholders, with named owners and remediation timelines.
    Cross-Functional & Partner Management
    • Work across a large stakeholder group spanning two parent companies and the JV - IT, Legal, Facilities, Internal Audit, HR, and engineering teams - and coordinate with 15-30+ named control owners for evidence collection.
    • Manage external partners: certification bodies (accredited ISO/TISAX auditors), external consultants, and vendors - tracking written deliverables, due dates, and response SLAs.
    • Maintain accurate, audit-ready documentation and program tracking in the team's tooling (e.g., Jira, Confluence, Google Workspace).
Qualifications
  • 5 years of experience in governance, risk, and compliance (GRC), IT/information security compliance, IT audit, or a closely related function.
  • Bachelor's degree or equivalent practical experience.
  • Working knowledge of ISO/IEC 27001/27002, TISAX and the NIST Cybersecurity Framework, including risk assessment and treatment concepts and control mapping.
  • Hands-on experience supporting or coordinating audits and certifications: evidence collection, control validation, and corrective-action tracking.
  • Experience operating or maintaining a risk register and driving remediation items to closure with accountable owners.
  • Strong documentation, organization, and project-tracking skills, with the ability to manage multiple concurrent deadlines.
  • Excellent written and verbal communication; able to work with both technical and non-technical stakeholders across a complex, multi-entity organization.
  • Ability and willingness to travel domestically and internationally up to a few weeks per quarter.

Preferred Qualifications:
  • Professional certification such as CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.
  • Hands-on experience with GRC/compliance tooling such as ServiceNow GRC, OneTrust, Vanta, Drata, Archer, AuditBoard, or ZenGRC.
  • Automotive industry experience, especially TISAX/VDA ISA assessments, UNECE R155/R156, ISO/SAE 21434, or IATF 16949.
  • Experience coordinating external auditors, certification bodies, or consultancies and managing deliverables to SLAs.
  • Proficiency with Jira, Confluence, and Google Workspace.
  • Experience in a fast-paced, high-growth, or joint-venture/multi-entity environment.
Travel
  • Travel up to a few weeks each quarter to company sites in Southern California, Northern California, Vancouver (BC), and Belgrade (Serbia) to support on-site audits, physical security walkthroughs, evidence collection, and stakeholder coordination.
  • Peak travel aligns with audit windows; a valid passport and the ability to travel internationally are required.
Total Rewards

We build the exceptional - and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.

Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.

In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees - including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.

External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.

Similar Jobs

More Jobs at Rivian and Volkswagen Group Technologies

More Enterprise Technology Jobs

Find similar Sr. GRC Analyst-Enterprise Cybersecurity jobs: